CVE-2025-70797: XSS
Published Apr 9, 2026
·Updated
Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] parameters.
Affected Software
2 affected components
Limesurvey LimeSurvey=6.15.20+251021
Limesurvey LimeSurvey=6.15.20-251021
Event History
Apr 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70797?
CVE-2025-70797 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-70797?
To fix CVE-2025-70797, upgrade to the latest version of LimeSurvey that addresses this vulnerability.
3
What are the potential impacts of CVE-2025-70797?
The potential impacts of CVE-2025-70797 include unauthorized access and control over the LimeSurvey installation.
4
Who is affected by CVE-2025-70797?
LimeSurvey version 6.15.20+251021 users are affected by CVE-2025-70797.
5
What security measures can mitigate CVE-2025-70797?
Implementing input validation and content security policies can help mitigate CVE-2025-70797.